3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-47117
label-studio General ⚡ nuclei
7.5
HIGH
EPSS
65.8%
2023 CWE-200 0 PoCs

Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token

CVE-2023-28432
🔥 KEV minio Cloud ⚡ nuclei
7.5
HIGH
EPSS
94.0%
2023 CWE-200 24 PoCs

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

CVE-2023-38952
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
15.3%
2023 1 PoC

Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege restrictions between non-admin and admin users are not enforced and any authenticated user can leverage admin functions without restriction by making direct requests to administrative endpoints.

CVE-2023-27639
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
81.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without restriction on the extension and path). Only files that can be parsed in XML can be opened. This is exploited in the wild in March 2023.

CVE-2023-6505
Migrate WordPress Website & Backups Web Windows ⚡ nuclei
7.5
HIGH
EPSS
73.8%
2023 1 PoC

The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.

CVE-2023-33510
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
71.5%
2023 1 PoC

Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.

CVE-2023-1719
Bitrix24 Web ⚡ nuclei
7.5
HIGH
EPSS
86.1%
2023 CWE-665 1 PoC

Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.

CVE-2023-43261
Software Genérico Networking ⚡ nuclei
7.5
HIGH
EPSS
93.1%
2023 3 PoCs

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

CVE-2023-6021
ray-project/ray Web ⚡ nuclei
7.5
HIGH
EPSS
87.3%
2023 CWE-29 2 PoCs

LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

CVE-2023-34092
vite General ⚡ nuclei
7.5
HIGH
EPSS
44.8%
2023 CWE-50 1 PoC

Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the Vite root-path of the application including the default `fs.deny` settings (`['.env', '.env.*', '*.{crt,pem}']`). Only users explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected, and only files in the immediate Vite project root folder could be exposed. This issue is fixed in vite@4.3.9, vite@4.2.3

CVE-2023-31059
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
91.2%
2023 1 PoC

Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.

CVE-2023-35844
Software Genérico Networking ⚡ nuclei
7.5
HIGH
EPSS
92.3%
2023 3 PoCs

packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.

CVE-2023-27179
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
85.8%
2023 1 PoC

GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

CVE-2023-0678
phpipam/phpipam Web ⚡ nuclei
7.5
HIGH
EPSS
67.6%
2023 CWE-862 0 PoCs

Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.

CVE-2023-35843
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
92.0%
2023 4 PoCs

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

CVE-2023-32235
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
94.1%
2023 2 PoCs

Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/web/middleware/static-theme.js.

CVE-2023-38950
🔥 KEV Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
83.4%
2023 0 PoCs

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

CVE-2023-6266
BackupBliss – Backup & Migration with Free Cloud Storage Web Cloud Windows ⚡ nuclei
7.5
HIGH
EPSS
26.8%
2023 CWE-200 0 PoCs

The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to download back-up files which can contain sensitive information such as user passwords, PII, database credentials, and much more.

CVE-2023-40211
Post Grid Combo – 36+ Gutenberg Blocks General ⚡ nuclei
7.5
HIGH
EPSS
31.5%
2023 CWE-200 0 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.

CVE-2023-38205
🔥 KEV ColdFusion General ⚡ nuclei
7.5
HIGH
EPSS
94.2%
2023 CWE-284 0 PoCs

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.